Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Jul 25th, 2026
Feed Source
Detection Method is
Rule Name & Severity
Author
Last Updated
Labels
Suspicious invoice reference with missing or image-only attachments
Sublime Security
6mo ago
Jan 12th, 2026
Suspicious VBA macros from untrusted sender
Sublime Security
6mo ago
Jan 12th, 2026
URI protocol handler: search-ms
Sublime Security
6mo ago
Jan 12th, 2026
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
Sublime Security
6mo ago
Jan 12th, 2026
X (Twitter) impersonation with credential phishing motives
Sublime Security
2mo ago
May 15th, 2026